Skip to content

[Question]: Mitigate CVE-2025-48384 - Windows agents ships vulnerable git versions #5304

@pefoo

Description

@pefoo

Describe your question

The windows agents ship a git version that is vulnerable to CVE-2025-48384

The vulnerable version is hard coded here

How can we mitigate this issue? Are there plans to release a new agent version that works for on-prem setups with a newer git version?

Versions

  • 3.238.0
  • 3.244.1
  • 4.260.0 (latest as of now)

Environment type (Please select at least one enviroment where you face this issue)

  • Self-Hosted
  • Microsoft Hosted
  • VMSS Pool
  • Container

Azure DevOps Server type

Azure DevOps Server (Please specify exact version in the textbox below)

Operation system

Windows

Version controll system

git

Azure DevOps Server Version (if applicable)

2022.2 (AzureDevopsServer_20240806.7)

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions